| ▲ | moonlet 4 hours ago | ||||||||||||||||
I am so sick of the ‘sandboxed’ AI-infra meme. A container is not a sandbox. A chroot is not a sandbox. A VM is also not a sandbox. A filesystem is also also not a sandbox. You can sandbox an application, you can run an application in a secure context, but this is not a secure context the author is describing, firstly, and secondly they haven’t described any techniques for sandboxing unless that part of the page didn’t load for me somehow. | |||||||||||||||||
| ▲ | Imustaskforhelp 42 minutes ago | parent | next [-] | ||||||||||||||||
I recently had a question about what AI sandboxes use and I think Modal uses gvisor under the hood and I think others use firecracker/generally favour it as well Firecracker kind of ends up being in the VM categories and I would place gvisor in a similar category too under the VM So in my opinion, VM's are sandboxes. Of course there is also libriscv https://github.com/libriscv/libriscv which is a sandbox (The fastest RISC-V sandbox) There is also https://github.com/Zouuup/landrun Run any Linux process in a secure, unprivileged sandbox using Landlock. Think firejail, but lightweight, user-friendly, and baked into the kernel. Your mileage may vary but I consider firecracker to be the AI sandbox usually. Othertimes it can be that they abstract on a cloud provider and open up servers in that or similar (I feel E2B does this on top of gcp) | |||||||||||||||||
| ▲ | jakobem 4 hours ago | parent | prev | next [-] | ||||||||||||||||
Didn’t mean to say this is a sandbox, it certainly isn’t, this is just an illustration on how to bridge the gap and make things available in a file system from the source of truth of your application. There is tons of more complexity to sandboxing, I agree! | |||||||||||||||||
| |||||||||||||||||
| ▲ | tptacek 4 hours ago | parent | prev | next [-] | ||||||||||||||||
Wait, can you provide the positive definition for "sandbox" you're relying on here? | |||||||||||||||||
| |||||||||||||||||
| ▲ | lagniappe 3 hours ago | parent | prev [-] | ||||||||||||||||
Please brother may i have some pledge unveil | |||||||||||||||||